74 known vulnerabilities · sorted by CVSS score
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption in WLAN Host while processing RRM beacon on the AP.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption in Core while processing control functions.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption in Kernel while parsing metadata.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory corruption while loading an ELF segment in TEE Kernel.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Transient DOS while parse fils IE with length equal to 1.
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.